CVE-2026-30457: Code Injection
Published Mar 26, 2026
·Updated
An issue in the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2 allows attackers to execute arbitrary code via crafted PHP code.
Affected Software
3 affected components
Daylight Studio FuelCMS=1.5.2
TheDayLightStudio Dwoo=1.1.0
TheDayLightStudio Fuel CMS=1.5.2
Event History
Mar 26, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-30457?
CVE-2026-30457 has a critical severity score of 9.8 according to CVSS 3.1.
2
How do I fix CVE-2026-30457?
To fix CVE-2026-30457, you should update Daylight Studio FuelCMS to the latest version that addresses this vulnerability.
3
What type of vulnerability is CVE-2026-30457?
CVE-2026-30457 is classified as a code injection vulnerability, allowing attackers to execute arbitrary code.
4
What components are affected by CVE-2026-30457?
CVE-2026-30457 affects the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2.
5
Can CVE-2026-30457 lead to data compromise?
Yes, CVE-2026-30457 can lead to significant data compromise due to its capabilities for arbitrary code execution.